4 ms·
> Backups are annoying and unglamorous Three years ago, after doing YC Startup School, I built https://www.borgbase.com https://www.borgbase.com to offer the s
by m3nu 5y ago
> Backups are annoying and unglamorous
Three years ago, after doing YC Startup School, I built https://www.borgbase.com https://www.borgbase.com to offer the simple, but secure backup service I wanted myself. Today it’s a viable business and my customers are all great and value backups as essential part of their own business. Wouldn’t want to be in any other “more glamorous” corner of the industry. Also kudos to anyone - partner or competitor - working in this “unglamorous” space. You’re all doing great work.
- novok 5y agoDo you do offsite offline backups too with verification? What if your infra gets really hacked and they wipe out all of your customer's backup data everywhere? Just because borg clients have append only modes, it doesn't stop them from deleting the raw files on your drives.
- m3nu 5y agoIf a storage server gets p0wned, the raw data could be deleted. That's true for every cloud provider. What's important, they still can't read the backup, since it's encrypted on the client. Storage servers are also isolated from each other and in different DCs, cities and regions. Additional offline backups aren't really feasible past a certain data volume and daily change/velocity. I'd still encourage everyone to have them for their own essential data in addition to a cloud backup. E.g. by burning it to BluRay or tape (3-2-1 rule). You can see find my own, more philosophical discussion, of the topic here: https://docs.borgbase.com/strategy/ https://docs.borgbase.com/strategy/. There I also distinguish between operational backups and archives. BorgBase is focused on the former. Offline backups are more suited for the latter.
- citrin_ru 5y ago> If a storage server gets p0wned, the raw data could be deleted. That's true for every cloud provider. It's not hard to create a cloud backup service where delete requires separate credentials which are not used in day-to-day operations (and so can be kept secure). And without these credentials a backup is kept N days and cannot be deleted or overwritten. Don't know if anyone do this, though.
- m3nu 5y agoYou can do it with S3 policies. But that's already at the application level. The question above was about the server level below that.
- fabflying 5y agoWas just looking for this, will give it a go
- neolog 5y agoHow did you figure out your pricing strategy?
- m3nu 5y agoPrices are fairly similar in this industry. So not much to decide. Early clients did push me to add a medium plan which turned out to be popular.